First published: Wed Nov 24 2021(Updated: )
Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack the authentication of Administrator and delete Administrator via a specially crafted web page.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
EC-CUBE EC-CUBE | >=2.11.0<=2.17.1 | |
composer/ec-cube/ec-cube | >=2.11.0<=2.17.1 | 2.17.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-20842.
The severity of CVE-2021-20842 is medium with a CVSS score of 6.5.
The affected software is EC-CUBE 2 series versions 2.11.0 to 2.17.1.
An attacker can exploit CVE-2021-20842 by crafting a specially designed web page to hijack the authentication of an Administrator and delete the Administrator.
Yes, you can find more information about CVE-2021-20842 at the following references: [JVN](https://jvn.jp/en/jp/JVN75444925/index.html) and [EC-CUBE website](https://www.ec-cube.net/info/weakness/20211111/).